Skip to content

Changelog

View as MarkdownAgent setup
Subscribe to RSS

2026-10-09


Failed detections field available in Rules

You can now use cf.appsec.request.failed_detections to control how your rules handle requests when a security detection reports a failure.

The field is an Array<String> of detection IDs that reports failures from content scanning, WAF attack score, attack signature detection, leaked credentials detection, and AI prompt detections for personally identifiable information (PII), prompt injection, custom topics, and unsafe topics.

The field does not alter the existing behavior of detections. Use it in rules to choose how to handle requests with reported failures.

When no failures are reported, the field returns []. You can use it on all plans, but your plan must still include the detections and rule features you want to use.

Supported rules:

  • Custom rules at the zone and account levels
  • Rate limiting rules at the zone and account levels
  • Request Header Transform Rules at the zone level

Match any reported failure:

len(cf.appsec.request.failed_detections) gt 0

Match a reported leaked credentials detection failure:

any(cf.appsec.request.failed_detections[*] eq "waf_credential_check")

For more information, refer to the Failed detections field reference.

2026-10-07


Updated unsafe topic detection for AI Security for Apps

AI Security for Apps now supports an updated set of categories for detecting unsafe topics in incoming prompts.

The values available in cf.llm.prompt.unsafe_topic_categories have changed. Existing WAF custom rules remain valid, but rules that reference a removed or renamed category will no longer match that category. Review any rules that use this field and update their expressions to use the currently supported values.

For category descriptions and configuration guidance, refer to Unsafe topics.

2026-10-06


WAF Release - 2026-10-06

This release introduces a new detection to mitigate a heap-based buffer overflow vulnerability in F5 BIG-IP, and enhances existing command injection protections by incorporating tested beta logic into the baseline rule.

Key Findings

  • CVE-2026-94127: A heap-based buffer overflow vulnerability in F5 BIG-IP. Attackers can exploit this flaw to execute arbitrary code on the affected system.
RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/ACommand Injection - Generic 8 - uri - BetaLogBlockThis rule is merged into the original rule "Command Injection - Generic 8 - uri" (ID: ).
Cloudflare Managed RulesetN/AF5 BIG-IP - UnAuth Heap-Overflow - CVE:CVE-2026-94127LogBlockThis is a new detection.
Cloudflare Managed RulesetN/ANext.js - Cache Poisoning - CVE:CVE-2026-94543BlockBlockRule metadata description refined. Detection unchanged.

2026-10-01


WAF Release - 2026-10-01 - Emergency

This update provides immediate defense against a vulnerability affecting Citrix NetScaler ADC and Gateway appliances, deploying protection against improper input validation vectors.

Key Findings

  • CVE-2026-88771: An improper input validation vulnerability affecting Citrix NetScaler ADC and Gateway allows an unauthenticated attacker to execute arbitrary commands.

Impact

We strongly recommend that administrators apply the latest versions to fully secure origin servers. Additionally, customers should review configurations against applicable preconditions and follow standard incident response processes if signs of compromise are identified.

Detailed Rule Changes

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/ACitrix Netscaler ADC and Gateway - Improper input validation - CVE:CVE-2026-88771N/ABlockThis is a new detection.

2026-09-30


WAF Release - 2026-09-30

This release introduces new detections to enhance protection against a specific GitLab path traversal vulnerability, alongside advanced generic rules targeting HTTP request smuggling, directory traversal, and command injection attempts.

Key Findings

  • CVE-2026-85706: A path traversal vulnerability affecting GitLab.
RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/ABroken Access Control - Directory TraversalLogBlockThis is a new detection.
Cloudflare Managed RulesetN/AHTTP Request Smuggling - Request Body Anomaly - BetaLogBlockThis rule is merged into the original rule "HTTP/2 Request Smuggling - Request Body Anomaly" (ID: ).
Cloudflare Managed RulesetN/ACommand Injection - Generic 8 - body - BetaDisabledDisabledThis rule is merged into the original rule "Command Injection - Generic 8 - body" (ID: ).
Cloudflare Managed RulesetN/AGitLab - Path Traversal- CVE:CVE-2026-85706LogBlockThis is a new detection.
Cloudflare Managed RulesetN/AGeneric - Request routing cache inconsistencyN/ABlockThis is a new detection.

2026-09-25


WAF Release - 2026-09-25 - Emergency

This update provides immediate defense against critical vulnerabilities affecting WordPress and JFrog Artifactory, including path traversal, local file inclusion (LFI), cross-site scripting (XSS), and authentication bypass exploits.

Key Findings

  • CVE-2026-87902: A high-severity Path Traversal and Local File Inclusion (LFI) vulnerability affecting WordPress. Unauthenticated attackers can exploit this flaw to read arbitrary files on the host server, potentially exposing sensitive configuration data or system files.

  • CVE-2026-42018 & CVE-2026-82329: Critical authentication bypass vulnerabilities affecting JFrog Artifactory. Successful exploitation allows unauthenticated attackers to bypass security controls and achieve unauthorized access to the Artifactory instance.

Impact

We strongly recommend that administrators apply the latest vendor patches for WordPress and JFrog Artifactory to fully secure origin servers.

Detailed Rule Changes

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/AWordpress - Path Traversal, Local File Inclusion - CVE:CVE-2026-87902N/ABlockThis is a new detection.
Cloudflare Managed RulesetN/AWordpress - XSS - CommentN/ABlockThis is a new detection.
Cloudflare Managed RulesetN/AJFrog Artifactory - Authentication Bypass - CVE:CVE-2026-42018N/ABlockThis is a new detection.
Cloudflare Managed RulesetN/AJFrog Artifactory - Authentication Bypass - CVE:CVE-2026-82329N/ABlockThis is a new detection.

2026-09-22


WAF Release - 2026-09-22

This release introduces new threat detections to enhance protection against Server-Side Request Forgery (SSRF) attempts using non-standard IP notations or jar loopback payloads, alongside new defenses against Server-Side Template Injection (SSTI) targeting Jinja environments.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/ASSRF - Cloud,Link-Local non-standard IP notationLogBlockThis is a new detection.
Cloudflare Managed RulesetN/ASSRF - Block jar HTTP loopback payloadLogBlockThis is a new detection.
Cloudflare Managed RulesetN/ASSRF - Local non-standard IP notationLogBlockThis is a new detection.
Cloudflare Managed RulesetN/ASSTI - Jinja Dangerous Globals ChainLogBlockThis is a new detection.

2026-09-15


WAF Release - 2026-09-15

This release introduces new threat detections to enhance protection against command injection attempts, Server-Side Request Forgery (SSRF) targeting cloud metadata, and information disclosure within version control history.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/ASSRF - Cloud - 3LogBlockThis is a new detection.
Cloudflare Managed RulesetN/AVersion Control - Information Disclosure - BetaLogBlockThis rule is merged into the original rule "Version Control - Information Disclosure" (ID: ).
Cloudflare Managed RulesetN/ACommand Injection - Generic 10LogBlockThis is a new detection.

2026-09-10


WAF Release - 2026-09-10 - Emergency

This update provides immediate defense against a high-severity, actively exploited zero-day vulnerability targeting Adobe Commerce and Magento Open Source storefronts.

Key Findings

  • Adobe Commerce and Magento RCE (CVE-2026-75650 / "StyleSmuggler"): Unauthenticated Remote Code Execution (RCE) vulnerability caused by improper neutralization of special elements in the platform's template engine. Unauthenticated attackers can inject arbitrary PHP payloads through style properties to execute system commands and deploy persistent malware.

Impact

This emergency rule provides immediate edge-level mitigation and virtual patching, origin applications must be urgently updated. We strongly recommend to apply the hotfix outlined in Adobe Security Bulletin APSB26-146 and immediately rotate all potentially exposed encryption keys, integration tokens, and system credentials, as patching alone does not remediate an existing compromise.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/AAdobe Commerce - Remote Code Execution - CVE:CVE-2026-75650N/ABlock

This is a new detection.

2026-09-08


WAF Release - 2026-09-08

This release enhances detection logic for existing rules targeting Next.js remote code execution (RCE) vulnerabilities by consolidating active beta rules into baseline signatures.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/ANext.js - Image Optimizer Remote Code Execution via Crafted AVIF - BetaLogBlockThis rule is merged into the original rule "Next.js - Image Optimizer Remote Code Execution via Crafted AVIF" (ID: ).
Cloudflare Managed RulesetN/ANext.js - Remote Code Execution - CVE:CVE-2026-75604 - BetaLogBlockThis rule is merged into the original rule "Next.js - Remote Code Execution - CVE:CVE-2026-75604" (ID: ).

2026-09-07


Enforce positive security with Application Profiles

Application Profiles add a positive-security layer to Cloudflare WAF. Instead of looking only for requests that resemble known attacks, Application Profiles learn what valid requests to your application look like and identify traffic that deviates from the expected structure.

The first available profile type, Schema Profiles, can learn path variables, query parameters, headers, cookies, JSON bodies, and form-encoded bodies. Profiles model field types and constraints such as numeric ranges, string lengths, and character classes. After a profile becomes available, an always-on detection classifies requests as conforming or non-conforming without blocking traffic.

Use Profile Analysis in Security Analytics to review conformance trends and sampled violation details before enforcing a profile. When you are ready to mitigate traffic, use a Custom Rule to scope enforcement by hostname, path, operation, or other security signals such as Attack Score.

Customers with API Security already have access to Schema Profiles through Schema Learning and Schema Validation. Cloudflare is also opening a closed beta to invited Enterprise customers without API Security. Contact your Cloudflare account team to express interest.

For more information, refer to Application Profiles.

2026-09-07


Attack Signature Detection is now available in Early Access

Attack Signature Detection is now available in Early Access. It evaluates requests against Cloudflare attack signatures and records matches without applying a mitigation action, allowing you to investigate detected traffic before deciding how to respond.

In Security Analytics > Attack Analysis, you can review matching signature references, categories, confidence levels, and request outcomes. You can then use these fields in Security Rules and combine them with request properties such as hostname, path, and HTTP method to apply scoped mitigation.

Attack Signature Detection uses the same signature definitions as Cloudflare Managed Rules, but it does not inherit your Managed Rules actions, overrides, or deployment configuration. Managed Rules remain the recommended baseline protection during Early Access.

Contact your Cloudflare account team to request access. For more information, refer to Attack Signature Detection.

2026-09-01


Updated PII detection for AI Security for Apps

AI Security for Apps now supports an updated set of categories for detecting personally identifiable information (PII) in incoming prompts.

The values available in cf.llm.prompt.pii_categories have changed. Existing WAF custom rules remain valid, but rules that reference a removed or renamed category will no longer match that category. Review any rules that use this field and update their expressions to use the currently supported values.

For the complete category list and configuration guidance, refer to PII detection.

2026-09-01


WAF Release - 2026-09-01

This release introduces a new threat detection to enhance protection against SQL injection (SQLi) attempts exploiting complex query syntax.

Key Findings

  • SQLi Protection: Improved coverage for SQL injection patterns involving WHERE comparisons combined with WITH clauses.
RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/ASQLi - WHERE Comparison With WITH ClauseLogBlockThis is a new detection.

2026-08-26


WAF Release - 2026-08-26 - Emergency

This emergency release updates an existing Next.js remote code execution rule to identify CVE-2026-75604 and adds a new rule for remote code execution in the Next.js Image Optimizer via crafted AVIF images.

Key Findings

  • CVE-2026-75604 affects Windows-hosted Next.js applications using both the Pages Router and App Router without Cache Components and can lead to unauthenticated remote code execution.

  • GHSA-2xp9-vwfh-vxw4 affects the Next.js Image Optimizer and can lead to unauthenticated remote code execution when it optimizes an attacker-controlled AVIF image.

Impact

Next.js recommends updating to version 16.3.3 or 15.5.24 to address these vulnerabilities.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/ANext.js - Remote Code Execution - CVE:CVE-2026-75604BlockN/ARule metadata description refined. Detection unchanged.
Cloudflare Managed RulesetN/ANext.js - Image Optimizer Remote Code Execution via Crafted AVIFN/ABlockThis is a new detection.

2026-08-25


WAF Release - 2026-08-25

This release moves four new detections from Log to Block, merges the XSS, HTML Injection - Script Tag - Beta rule into the original rule, and adds a Generic Rules - Remote Code Execution rule in Block mode.

Key Findings

  • Four new detections move from Log to Block: HTTP/2 Request Smuggling - Request Body Anomaly and XSS - JavaScript Event Handler Coercion across Headers, Body, and URI.

  • The XSS, HTML Injection - Script Tag - Beta rule is merged into the original rule.

  • A Generic Rules - Remote Code Execution detection is added in Block mode.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/AHTTP/2 Request Smuggling - Request Body AnomalyLogBlockThis is a new detection.
Cloudflare Managed RulesetN/AXSS - JavaScript Event Handler Coercion - HeadersLogBlockThis is a new detection.
Cloudflare Managed RulesetN/AXSS - JavaScript Event Handler Coercion - BodyLogBlockThis is a new detection.
Cloudflare Managed RulesetN/AXSS - JavaScript Event Handler Coercion - URILogBlockThis is a new detection.
Cloudflare Managed RulesetN/AXSS, HTML Injection - Script Tag - BetaLogBlockThis rule is merged into the original rule "XSS, HTML Injection - Script Tag" (ID: ).
Cloudflare Managed RulesetN/AGeneric Rules - Remote Code ExecutionN/ABlockThis is a new detection.

2026-08-20


Leaked credentials detection now scans Authorization headers

Leaked credentials detection now scans the Authorization request header for Basic Authentication credentials. Previously, the detection only inspected request bodies, query strings, and headers for well-known web applications or custom detection locations, which meant credentials sent through HTTP Basic Authentication were not covered by default.

This new default scan location decodes the Authorization: Basic <credentials> header and compares the extracted username and password against Cloudflare's database of leaked credentials, the same way as other default scan locations. Matches populate the existing leaked credentials fields, such as cf.waf.credential_check.password_leaked, and trigger the Exposed-Credential-Check managed transform header if configured, so you can reuse existing custom rules and rate limiting rules without changes.

This change was applied automatically for zones with leaked credentials detection enabled. No configuration changes are required.

For more information, refer to Leaked credentials detection.

2026-08-17


WAF Release - 2026-08-17

This release updates WordPress remote code execution rule metadata in the Cloudflare Managed Ruleset and Cloudflare Free Ruleset to identify CVE-2026-65640.

Key Findings

  • CVE-2026-65640: A remote code execution vulnerability affecting WordPress core and plugin components. Remote, unauthenticated attackers can execute arbitrary system commands to gain unauthorized access or establish backdoors on host servers.

Impact

The WordPress changes update rule metadata only; detection behavior and actions remain unchanged.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/AWordpress - Remote Code Execution - CVE:CVE-2026-65640BlockN/ARule metadata description refined. Detection unchanged.
Cloudflare Free RulesetN/AWordpress - Remote Code Execution - CVE:CVE-2026-65640BlockN/ARule metadata description refined. Detection unchanged.

2026-08-11


WAF Release - 2026-08-11

This release introduces new protection for a remote code execution vulnerability in vBulletin and improves two existing detections.

Key Findings

  • A new detection provides protection against vBulletin CVE-2026-61511.
  • Two existing detections have been improved to strengthen coverage.

Impact

Successful exploitation of CVE-2026-61511 may lead to remote code execution on affected vBulletin systems, potentially resulting in unauthorized access, data exposure, service disruption, and broader compromise of the hosting environment. Administrators are strongly encouraged to apply vendor updates and recommended mitigations.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/AvBulletin - Remote Code Execution - CVE:CVE-2026-61511LogBlockThis is a new detection.
Cloudflare Managed RulesetN/AVersion Control - Information Disclosure - BetaLogBlockThis rule is merged into the original rule "Version Control - Information Disclosure" (ID: )
Cloudflare Managed RulesetN/AvBulletin - Code Injection - Invalid image format - CVE:CVE-2019-17132 - BetaLogBlockThis rule is merged into the original rule "vBulletin - Code Injection - Invalid image format - CVE:CVE-2019-17132" (ID: )

2026-08-07


WAF Release - 2026-08-07

This release updates WordPress XSS rule metadata in the Cloudflare Managed Ruleset and Cloudflare Free Ruleset to identify XSS2Shell (CVE-2026-64638). It also disables the Command Injection - Obfuscation rule.

Key Findings

  • CVE-2026-64638: A pre-authentication reflected cross-site scripting vulnerability affecting the WordPress login screen. Exploitation requires social engineering and explicit interaction by the target user. Under additional conditions, it may be escalated to remote code execution.

Impact

The WordPress changes update rule metadata only; detection behavior and actions remain unchanged.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/AWordpress - XSS - CVE:CVE-2026-64638BlockN/ARule metadata description refined. Detection unchanged.
Cloudflare Free RulesetN/AWordpress - XSS - CVE:CVE-2026-64638BlockN/ARule metadata description refined. Detection unchanged.
Cloudflare Managed RulesetN/ACommand Injection - ObfuscationBlockDisabledDetection logic has been deprecated

2026-08-04


WAF Release - 2026-08-04

This release introduces new rules and updates Microsoft SharePoint RCE alongside enhanced SSRF cloud protection rule actions.

Key Findings

  • CVE-2026-50522: An insecure deserialization vulnerability in Microsoft SharePoint Server. This may allow an unauthenticated attacker to execute arbitrary code using crafted requests.
  • CVE-2026-66066: An improper input processing vulnerability in Ruby on Rails Active Storage image variant transformations. This may allow an unauthenticated attacker to perform arbitrary file reads and achieve Remote Code Execution (RCE) using maliciously crafted payload requests.
  • Generic Cloud Protections: Added improved detection logic targeting Server-Side Request Forgery (SSRF) in cloud-hosted applications.
RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/AMicrosoft SharePoint - Remote Code Execution - CVE:CVE-2026-50522LogBlock

This is a new detection.

Cloudflare Managed RulesetN/ARails - Arbitrary File Read & RCE - CVE:CVE-2026-66066BlockBlock

This was labeled as File Upload - RCE.

Cloudflare Managed RulesetN/ASSRF - Local - 2 - BetaDisabled -

This detection has been removed.

Cloudflare Managed RulesetN/ASSRF - Cloud - BetaDisabled -

This detection has been removed.

Cloudflare Managed RulesetN/ASSRF - Cloud - 2 - BetaDisabled -

This detection has been removed.

Cloudflare Managed RulesetN/ASSRF - CloudDisabledBlock

We are changing the action for this rule from Disabled to BLOCK

Cloudflare Managed RulesetN/ASSRF - Local - BetaDisabled -

This detection has been removed.

2026-07-29


WAF Release - 2026-07-29

This release introduces new rules and updates existing threat signatures to provide targeted protections for vulnerabilities in Nuxt Server Island components and Alibaba Fastjson deserialization routines, alongside enhanced protections for cloud metadata Server-Side Request Forgery (SSRF) and obfuscated command injection attempts.

Key Findings

  • Nuxt Server Island - RCE(GHSA-9473-5f9j-94wq): An unauthenticated vulnerability in Nuxt Server Islands where remote attackers can supply arbitrary component names or props to endpoints. Manipulating these parameters allows unauthenticated component Remote Code Execution (RCE) on the server.

  • Alibaba Fastjson JSONType Remote Code Execution: A unauthenticated remote code execution vulnerability in Alibaba Fastjson (≤ 1.2.83) during JSON deserialization. Under default configurations, attackers can execute arbitrary system commands, bypassing traditional classpath and gadget-based defenses.

  • Generic Protections (SSRF & Command Injection): Added improved detection logic targeting Server-Side Request Forgery (SSRF) in cloud-hosted applications, alongside new rules targeting obfuscated command injection patterns across request parameters.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/ASSRF - Cloud - BetaLogBlock

This is an improved detection.

Cloudflare Managed RulesetN/ACommand Injection - ObfuscationLogBlock

This is a new detection.

Cloudflare Managed RulesetN/AAlibaba Fastjson JSONType Remote Code Execution - BodyLogBlock

This is a new detection.

Cloudflare Managed RulesetN/ANuxt Server Island - RCEN/ABlock

This is a new detection.This was labeled as Generic Rules - RCE.

Cloudflare Managed RulesetN/AGeneric Rules - RCEN/ABlock

This is a new detection.

Cloudflare Managed RulesetN/AGeneric Rules - XSSN/ABlock

This is a new detection.

Cloudflare Managed RulesetN/AFile Upload - RCEN/ABlock

This is a new detection.

Cloudflare Free RulesetN/AGeneric Rules - RCEN/ABlock

This is a new detection.

Cloudflare Free RulesetN/AGeneric Rules - XSSN/ABlock

This is a new detection.

Cloudflare Free RulesetN/AFile Upload - RCEN/ABlock

This is a new detection.

2026-07-21


WAF Release - 2026-07-21

This release introduces new rules for vulnerabilities in Adobe ColdFusion, Next.js, WordPress alongside updates to existing rules thereby providing enhanced generic protections against Server-Side Request Forgery (SSRF), Local File Inclusion (LFI), and Cross-Site Scripting (XSS).

WAF and framework adapter mitigations for Next.js vulnerabilities

Multiple security vulnerabilities ↗︎ were disclosed and patched by the Next.js team through July 2026 security release. These include denial of service, middleware and proxy bypass, server-side request forgery, information disclosure, and cache poisoning across a range of severities.

Several of the disclosed vulnerabilities are not possible to block at WAF layer,we strongly recommend updating your application and its dependencies immediately. Patched versions are available through v16.2.11 (Active LTS) and v15.5.21 (Maintenance LTS) to address these issues.

AdvisoryCVESeverityIssueWAF Coverage
Denial of Service in App Router using Server ActionsCVE-2026-64641High

Crafted requests targeting Next.js applications using App Router with at least one Server Action can lead to excessive CPU usage. The CPU usage blocks processing of further requests in the same process, leading to Denial of Service.

WAF rule Next.js - DoS - CVE-2026-64641 () has been deployed to provide coverage.

Middleware / Proxy bypass in App Router applications using Turbopack and single localeCVE-2026-64642High

Next.js applications using App Router built with Turbopack and a single entry in config.i18n.locales are vulnerable to a middleware/proxy bypass. Accordingly, any authentication or security checks that a middleware/proxy may perform are bypassed.

This is a middleware bypass that unfortunately cannot be covered through Cloudflare WAF signature engine.

Server-Side Request Forgery in rewrites via attacker-controlled destination hostnameCVE-2026-64645High

A rewrites() or redirects() rule that builds its external destination hostname from request-controlled input can be pointed at an arbitrary hostname, regardless of the rule's hostname suffix. For rewrites, this behavior enables Server-Side Request Forgery (SSRF); for redirects, Open Redirect can be achieved.

Existing SSRF rules provide adequate coverage for this vulnerability, no tailored WAF rule was developed.

Server-Side Request Forgery in Server Actions on custom serversCVE-2026-64649High

When a Server Action forwards or redirects a request, an attacker can cause the server to send that outbound request to a malicious host (Server-Side Request Forgery). This requires the attacker’s request to control Host-associated headers.

WAF rule Next.js - SSRF - CVE-2026-64649 () has been deployed to provide coverage.

Denial of Service in the Image Optimization API using SVGsCVE-2026-64644Medium

When self-hosting Next.js with the default image loader, the Image Optimization API can optimize remotely hosted images if configured (not enabled by default). If those images contain malicious content, the images can cause CPU exhaustion in the /_next/image endpoint.

Malicious request is unfortunately indistinguishable from a legitimate image optimization request, so no WAF rule has been created to address this vulnerability.

Unbounded Server Action payload in Edge runtimeCVE-2026-64646Medium

A crafted request can lead to memory consumption on Server Actions in the Edge runtime. Next.js applications which use App Router and have at least one Server Action are affected.

Unfortunately there is no one size fits all rule that can be deployed through WAF in lieu of custom bodySizeLimit configurations, so no WAF rule has been created to address this vulnerability.

Unauthenticated disclosure of internal Server Function endpointsCVE-2026-64643Medium

In Next.js applications using App Router, Server Actions (use server) or use cache endpoint IDs can be globally disclosed. An attacker can use this for reconnaissance and as part of a broader attack chain.

WAF rule Next.js - Information Disclosure - CVE-2026-64643 () has been deployed to provide coverage.

Cache confusion of response bodies for requests with bodiesCVE-2026-64648Medium

A server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. This only applies for fetch calls of the shape fetch(new Request(init), aDifferentInit)

This is an application logic bug that unfortunately cannot be covered through Cloudflare WAF signature engine.

Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequencesCVE-2026-64647Medium

A server-side fetch with a request body may return a cached response body from a different request to the same URL but different body. This only applies when receiving request bodies which contain invalid UTF-8 characters.

This is an application logic bug that unfortunately cannot be covered through Cloudflare WAF signature engine.

Key Findings

  • CVE-2026-48276: A path traversal vulnerability in Adobe ColdFusion file upload mechanisms allows unauthenticated attackers to write or upload files to arbitrary locations outside designated directories on the origin server.

  • CVE-2026-48282: A path traversal vulnerability in Adobe ColdFusion enables unauthenticated attackers to manipulate directory sequences and access restricted system files on the host filesystem.

  • CVE-2026-60137: An unauthenticated SQL injection vulnerability affecting WordPress. Threat actors exploit unsanitized input parameters to execute arbitrary SQL queries, leading to unauthorized database access, record manipulation, or data exfiltration.

  • CVE-2026-63030: A remote code execution vulnerability affecting WordPress core and plugin components. Remote, unauthenticated attackers can execute arbitrary system commands to gain unauthorized access or establish backdoors on host servers.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/ASSRF - Restricted ProtocolLogBlock

This is a new detection.

Cloudflare Managed RulesetN/ASSRF - Obfuscated HostLogBlock

This is a new detection.

Cloudflare Managed RulesetN/ALFI - Path TraversalLogBlock

This is a new detection.

Cloudflare Managed RulesetN/AAdobe ColdFusion - File Upload Path Traversal - CVE:CVE-2026-48276LogBlock

This is a new detection.

Cloudflare Managed RulesetN/AAdobe ColdFusion - Path Traversal - CVE:CVE-2026-48282LogBlock

This is a new detection.

Cloudflare Managed RulesetN/AXSS — JS Bracket Concat Obfuscation - BodyLogDisabled

This is a new detection.

Cloudflare Managed RulesetN/AXSS — JS Bracket Concat Obfuscation - HeadersLogDisabled

This is a new detection.

Cloudflare Managed RulesetN/AXSS — JS Bracket Concat Obfuscation - URILogBlock

This is a new detection.

Cloudflare Managed RulesetN/AWordpress - SQL Injection - CVE:CVE-2026-60137N/ABlock

This was labeled as Generic Rules - SQLi.

Cloudflare Managed RulesetN/AWordpress - Remote Code Execution - CVE:CVE-2026-63030N/ABlock

This was labeled as Generic Rules - Unauthenticated RCE.

Cloudflare Free RulesetN/AWordpress - SQL Injection - CVE:CVE-2026-60137N/ABlock

This was labeled as Generic Rules - SQLi.

Cloudflare Free RulesetN/AWordpress - Remote Code Execution - CVE:CVE-2026-63030N/ABlock

This was labeled as Generic Rules - Unauthenticated RCE.

Cloudflare Managed RulesetN/ANext.js - Information Disclosure - CVE-2026-64643N/ABlock

This was labeled as Generic Rules - Information Disclosure.

Cloudflare Managed RulesetN/ANext.js - SSRF - CVE-2026-64649N/ABlock

This was labeled as Generic Rules - Auth Bypass - 2.

Cloudflare Managed RulesetN/ANext.js - Remote Code Execution - Cache ComponentsN/ABlock

This was labeled as Generic Rules - RCE.

Cloudflare Managed RulesetN/ANext.js - DoS - CVE-2026-64641N/ABlock

This was labeled as Generic Rules - DoS.

Cloudflare Managed RulesetN/AGeneric Rules - Command Execution - Body - BetaDisabled -

This detection has been removed.

Cloudflare Managed RulesetN/AGeneric Rules - Command Execution - Header - BetaDisabled -

This detection has been removed.

Cloudflare Managed RulesetN/AGeneric Rules - Command Execution - URI - BetaDisabled -

This detection has been removed.

2026-07-17


WAF Release - 2026-07-17 - Emergency

This emergency release adds a new managed rule to block active exploitation of a critical remote code execution (RCE) and SQL injection (SQLi) vulnerability found in popular web frameworks.

Key Findings

  • Generic Frameworks - Unauthenticated RCE: Attackers can execute arbitrary system commands with web server privileges by sending malicious input containing invalid path sequences during request processing.

  • Generic Frameworks - SQLi: Attackers can execute unauthorized database queries due to a failure to sanitize input values within request parameters.

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/AGeneric Rules - Unauthenticated RCEN/ABlockThis is a new detection.
Cloudflare Managed RulesetN/AGeneric Rules - SQLi N/ABlockThis is a new detection.
Cloudflare Free RulesetN/AGeneric Rules - Unauthenticated RCE N/ABlockThis is a new detection.
Cloudflare Free RulesetN/AGeneric Rules - SQLi N/ABlockThis is a new detection.

2026-07-14


WAF Release - 2026-07-14

This release introduces new rules targeting critical infrastructure vulnerabilities. These include an unauthenticated memory disclosure flaw in Citrix NetScaler ADC and Gateway (CVE-2026-8451) and a high-severity pre-authentication remote code execution (RCE) vulnerability in Progress Kemp LoadMaster (CVE-2026-8037).

Key Findings

  • CVE-2026-8451: An insufficient input validation vulnerability affects Citrix NetScaler ADC and NetScaler Gateway appliances configured as a SAML Identity Provider (IdP). Remote, unauthenticated attackers can exploit this flaw by sending malformed requests to trigger a memory overread, allowing them to leak chunks of sensitive data from adjacent appliance memory.

  • CVE-2026-8037: A critical OS command injection vulnerability in Progress Kemp LoadMaster load balancers allows unauthenticated remote attackers to achieve remote code execution (RCE).

RulesetRule IDLegacy Rule IDDescriptionPrevious ActionNew ActionComments
Cloudflare Managed RulesetN/ACitrix Netscaler ADC - Insufficient Input Validation - CVE:CVE-2026-8451LogBlock

This is a new detection.

Cloudflare Managed RulesetN/AProgress Kemp LoadMaster - Remote Code Execution - CVE:CVE-2026-8037LogBlock

This is a new detection.